Résumé
Mt. Gox was, at its peak, the exchange that handled most of the world's Bitcoin trading. On 7 February 2014 it froze withdrawals, and on 28 February it filed for bankruptcy in Tokyo, admitting that roughly 850,000 BTC, around $450 million at the time and tens of billions today, was gone. The collapse was not one dramatic heist but years of undetected drain through atrocious security and accounting: private keys stored carelessly, no real cold storage, no audited reserves, and books so broken the company did not know its own coins were leaking away. It is the original "not your keys, not your coins" lesson, and the reason exchange custody, proof of reserves, and real accounting exist as disciplines today.
How it happened
Mt. Gox (the name began as "Magic: The Gathering Online eXchange") grew almost by accident into the exchange handling something like 70% of all Bitcoin trades by 2013, run with very little engineering rigour. Underneath the dominance was a mess. Its private keys were poorly protected (an unencrypted wallet file was reportedly stolen as early as 2011, the year forensic investigators later pinned as the start of the theft), there was no meaningful cold storage, no audited reserves, and no reconciliation between what the books said it held and what was actually on the blockchain. The cracks showed early: in June 2011 an attacker used a compromised auditor account to crash the nominal Bitcoin price to a single cent and sell off coins, and the user database leaked days later.
The result was not a single break-in but a slow haemorrhage. Coins drained out over years through stolen keys and skimming, and the broken accounting simply hid it, Mt. Gox did not know its own balance was falling. When it finally collapsed, the company publicly blamed "transaction malleability," a quirk of Bitcoin that let a transaction's ID be altered to fake a failed withdrawal. But researchers at ETH Zurich found malleability could explain just 386 BTC. The real loss was long-running theft masked by an absence of any controls that would have caught it; blockchain forensics later showed the drain ran continuously from late 2011 until the reserves were practically empty by mid-2013.
The aftermath
About 850,000 BTC was gone (roughly 750,000 belonging to customers and 100,000 to the company), and around 200,000 BTC was later recovered in an old-format wallet, coins Mt. Gox still held but had simply lost track of, the clearest proof of how broken its accounting was. What followed was a decade of legal limbo: bankruptcy proceedings in Japan, and creditor repayments that, despite beginning in 2024, are still being worked through, with the trustee's deadline extended into 2026, all in Bitcoin now worth vastly more than when it was lost. In 2023 the US Department of Justice charged two Russian nationals, Alexey Bilyuchenko and Aleksandr Verner, not merely with laundering but with the hack itself, stealing at least 647,000 BTC from 2011; Bilyuchenko allegedly used the proceeds to help run BTC-e, a criminal exchange of its own. Mt. Gox's collapse cratered Bitcoin's price and credibility for years and became the cautionary tale every later exchange was measured against.
Why Mt. Gox still matters
Mt. Gox is the foundational custody lesson: a centralized exchange is a bank holding other people's money, but with none of a bank's controls unless it deliberately builds them. Keys sat on shared servers, the bulk of funds was never in cold storage, there was no proof of reserves and no reconciliation, so a multi-year drain went completely unseen. It gave the industry the phrase "not your keys, not your coins" and birthed the proof-of-reserves movement. The same custody failures echo in later exchange disasters like Bitfinex. The defences are now standard and still skipped: keep the overwhelming majority of funds in cold storage, use multisig or MPC signing, run continuous proof-of-reserves and ledger-to-chain reconciliation, never store keys on application servers, and alert on withdrawal anomalies.
Comment le corriger
- There is no clean "fix" for funds drained over years; the immediate response is to halt withdrawals, freeze the books, and bring in forensic accountants and law enforcement.
- Reconcile on-chain holdings against the ledger to establish the true shortfall, then rebuild custody from scratch with cold storage and multisig before resuming.
- Trace stolen coins on-chain (Mt. Gox's were eventually traced and prosecuted years later) and pursue recovery through exchanges and the courts.
Comment l’éviter
- Keep the overwhelming majority of customer funds in air-gapped cold storage; hot wallets hold only operational float.
- Use multisig or MPC/threshold signing so no single leaked key authorizes withdrawals.
- Run continuous proof-of-reserves and automated ledger-to-chain reconciliation to detect drain early.
- Rotate keys, segregate infrastructure, and never store wallet files or private keys on shared application servers.
- Enforce withdrawal rate limits, allowlists, and anomaly detection on outbound transactions.
Références
- https://blog.wizsec.jp/2015/04/the-missing-mtgox-bitcoins.html
- https://www.justice.gov/usao-sdny/pr/russian-nationals-charged-hacking-one-cryptocurrency-exchange-and-illicitly-operating
- https://en.bitcoin.it/wiki/Collapse_of_Mt._Gox
- https://www.coindesk.com/markets/2014/03/27/study-mt-gox-may-have-lost-just-386-btc-due-to-transaction-malleability
- https://www.npr.org/sections/thetwo-way/2014/02/28/283863219/mtgox-files-for-bankruptcy-nearly-500m-of-bitcoins-lost
Vulnérabilités liées
Tout Web3 →- CRITICALWEB3-PHEMEX-2025
On January 23, 2025, exchange Phemex lost about $85M (early estimates started near $29M before rising) after attackers drained hot wallets across roughly 11-16 blockchains in a synchronized series of more than 125 transactions consistent with a compromised set of hot-wallet private keys; Phemex said the affected signing devices were identified and isolated, pointing to compromised signing infrastructure rather than an on-chain contract flaw. The attacker prioritized high-value tokens and swapped freezable assets into non-freezable ones before any freezes could land. Cold wallets stayed secure and Phemex covered the losses, resuming operations within days under Fireblocks MPC custody with keys split across distributed nodes. Flow-of-funds tracing (Merkle Science) and on-chain analysts (ZachXBT, Arkham), later supported by the FBI, attributed the theft to North Korea's Lazarus Group: on February 22, 2025 the attackers consolidated proceeds from the subsequent Bybit hack into the existing Phemex hacker address, retroactively linking the two incidents on-chain. Stolen funds were laundered via Tornado Cash and not recovered.
- CRITICALWEB3-POLONIEX-2023
On November 10, 2023, the Justin Sun-linked exchange Poloniex lost roughly $120 million (estimates ranged $114 to $126 million) after attackers compromised a hot-wallet private key and swept tokens to attacker-controlled wallets. The drain hit a hot wallet labeled 'Poloniex 4,' with automated bots executing hundreds of unauthorized transactions that emptied multiple assets in just over an hour, a pattern indicating the signing key itself was in attacker hands rather than any contract bug. The exact intrusion path was not disclosed, but single-key-controlled hot wallets with inadequate signing thresholds let one compromised key authorize the mass outflow. Analysts including Elliptic attributed the theft to North Korea's Lazarus Group based on the attack methodology and a laundering signature of splitting token types across addresses before consolidating, and Justin Sun publicly linked the perpetrators to Lazarus. Poloniex offered a white-hat bounty for the funds' return; the attacker began moving funds (including ETH to Tornado Cash) and the bulk was not recovered, though Sun said losses would be reimbursed.
- CRITICALWEB3-MIXIN-NETWORK-2023
On September 23, 2023, Mixin Network lost about $200M (roughly $95M ETH, $24M BTC and $24M USDT among other assets) after attackers breached the database of the network's third-party cloud service provider, which held Mixin's deposit-address and hot-wallet private keys in a recoverable manner. With the database compromised, the attacker reconstructed the private keys and signed outbound transactions directly, sweeping over 11,400 deposit wallets from highest to lowest balance across more than 10,000 transactions; stolen USDT was swapped to roughly 23.5M DAI to break traceability. The weak link was the upstream cloud database acting as a single point of failure with recoverable keys, rather than a smart-contract bug or a direct private-key theft from Mixin itself (the provider is widely inferred to be Google Cloud but was never officially confirmed). Mixin engaged Google and SlowMist to investigate, suspended deposits and withdrawals, offered a $20M bounty, and announced a plan to reimburse 50% of affected user assets with the remainder issued as debt/bond tokens. The bulk of the funds was laundered and not recovered.
- CRITICALWEB3-COINEX-2023
On September 12, 2023, exchange CoinEx lost an estimated $54 to $70 million after attackers compromised its hot-wallet private keys, exploiting lax single-key hot-wallet security. CoinEx's own assessment preliminarily identified leakage of the hot-wallet private key as the cause; wallets controlled by a single key are especially exposed to phishing and malware, the favored access vectors of the attributed actor, and once the key leaked the attacker swept assets directly. The theft was attributed to North Korea's Lazarus Group: one of the CoinEx attacker addresses was reused from the Stake.com hack (FBI-confirmed Lazarus) and funds were bridged via infrastructure previously used by Lazarus, with the linkage confirmed by Elliptic, CertiK, SlowMist, ZachXBT and overlapping addresses tying CoinEx, Stake.com and Alphapo together. CoinEx absorbed the loss and fully reimbursed affected users without diluting its CET token, restoring full operations over the following months.
- CRITICALWEB3-ATOMICWALLET-2023
On June 3, 2023, users of Atomic Wallet, a non-custodial cryptocurrency wallet, lost over $100M (an early Elliptic estimate of ~$35M was later revised upward) across at least 5,500 accounts. Atomic Wallet never published a root cause, so the exact technical mechanism remains officially undisclosed and disputed; leading unconfirmed theories, consistent with a compromise of key generation or key exfiltration, include weak entropy or insufficient randomness in seed generation creating a brute-forceable keyspace, private keys or seeds being exfiltrated to a server (for example via logging), a supply-chain compromise of the app build, or fault attacks on the signing algorithm. Blockchain forensics firm Elliptic attributed the heist to North Korea's Lazarus Group with high confidence on June 6, 2023, based on laundering through the Sinbad mixer and Garantex and, most tellingly, stolen funds flowing into wallets already holding proceeds of prior Lazarus hacks; the FBI later supported this. Only a small portion (over $1M) was frozen and the bulk was not recovered. A class action (Colorado federal court) was later dismissed.
- CRITICALWEB3-KUCOIN-2020
On September 25, 2020, exchange KuCoin lost roughly $281 million in BTC, ETH and ERC-20 tokens after attackers gained access to the private keys controlling its hot wallets. KuCoin's own incident report confirmed the keys were exposed via a compromised server; the precise initial intrusion was not fully disclosed but is consistent with phishing or malware against personnel with key access, compounded by the operational weakness that the hot-wallet key pairs reportedly had not been rotated for around three years. Holding large balances in single-key-controlled hot wallets meant one key compromise allowed sweeping of multiple assets across chains. Chainalysis attributed the theft to North Korea's Lazarus Group, citing a structured money-laundering pattern (consistent sub-round-number payments to mixers and DeFi swaps via Uniswap) and deposit addresses shared with the Harvest Finance hack. KuCoin recovered the funds almost entirely: about 84% via on-chain tracking, token freezes and judicial action, with the remaining 16% covered by its insurance fund, leaving users unaffected.